.html does not escape any html input in these, leading to XSS attack vectors. Thanks to A Kai (@sixhundredns) for reporting the related issues. |
||
|---|---|---|
| .. | ||
| back-to-top.js | ||
| direction-detector.js | ||
| flash-messages.js | ||
| header.js | ||
| infinite-scroll.js | ||
| lightbox.js | ||
| notifications-badge.js | ||
| notifications.js | ||
| search.js | ||
| stream.js | ||
| timeago.js | ||